Back to skill

Security audit

域名DNS

Security checks for vulnerabilities and agentic risk

Overview

This DNS operations skill is not clearly malicious, but it asks for broad file and command authority while giving vague instructions for cloud/DNS changes, so it should be reviewed before installation.

Install only if you intend to use it for DNS/domain automation and are comfortable giving the agent command, file, network, and cloud-credential access. Before using it for record changes, domain registration, imports, exports, monitoring, or deployment work, require an explicit plan and confirmation for each state-changing action.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

High
Confidence
91% confidence
Finding
The activation/description text is overly broad and mismatched, expanding the skill from DNS operations into generic system monitoring, log analysis, alerts, and deployment management. In an agent context with read/exec/write tools, vague activation boundaries can cause the skill to trigger in unrelated workflows and perform or recommend sensitive operations, increasing the chance of unintended command execution or infrastructure changes.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The usage instructions tell the agent to choose an appropriate usage method and execute operations, but they provide no concrete trigger phrases, scope checks, or user-confirmation requirements. In a skill that implies DNS and cloud-side changes and has exec/write capability, this ambiguity makes accidental or overbroad activation more dangerous because the agent may act on loosely related prompts.

Static analysis

No suspicious patterns detected.